Process Details script

Prev Next

The Process Details script requests data about a specific process from host endpoints. This script can be requested for Windows or macOS host endpoints only. You cannot request Process Details data as a regular data acquisition but you can request this script from the Triage Viewer.

Note

Process Details script support is not provided for Linux host endpoints.

You can edit, reset, and export this script on the Data Acquisitions Script page, but this script cannot be copied.

HX_SSTypes_AcqProcDetails_scap.png

The following table describes the fields in this dialog box. At least one PID (process ID) or process name must be specified.

Field

Description

Acquire using

Select PID to specify a process ID. Select Process name to specify a process name.

Process PID

If PID was selected, specify the process ID to use when collecting process detail data.

Process name

If Process name was selected, specify the process name to use when collecting process detail data.

Note

The Process Detail dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.

Requesting process details

  1. Select Acquisitions in the Endpoint Security (HX) Web UI.

  2. Select a host.

    Note

    If you select multiple hosts, the Process Details acquisition option is not available. You can only request this script when a single host is selected.

  3. From the Triage collection acquired panel, click View Triage Summary to access the triage summary for the selected host.

  4. Click Acquire Process Details.

  5. From the Acquire using: menu, select PID if you want to specify a process ID or select Process name if you want to specify a process name.

    Important

    The data acquisition will only succeed if the process is still running. If the PID is reused by the operating system, the acquisition request could return a different process.

  6. Based on your previous selection, enter the process ID or the process name.

  7. In the Comment field, enter the reason you want to acquire the file and any details about the data acquisition request that you want to track.

  8. Click Acquire.

The Process Details dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.

You can view and download data returned for this request on the Acquisitions page in the Acquisition Detail area. See Requesting a Process Detail data acquisition. You can also review the data in the Audit Viewer. If you download the acquisition, you can review the data in Redline. The acquired data includes strings in memory for the process.